Compliance — SOC 2
SOC 2 Type II evidence — collected continuously, not assembled at audit time
ManySignal monitors all five Trust Services Criteria year-round. CC6.1 access control logs, CC7.2 anomaly detection evidence, CC7.3 alert evaluation records — all timestamped, auditor-readable, and exportable on demand.
What SOC 2 requires in plain language
Common Criteria (CC) — Security
The core of every SOC 2 audit. Covers logical access controls (CC6), anomaly detection (CC7), change management (CC8), and risk mitigation (CC9). These 32 criteria are the primary focus of ManySignal's continuous monitoring evidence.
Type II vs. Type I
Type I is a point-in-time assertion that controls are designed correctly. Type II covers a period (typically 12 months) and requires evidence that controls operated effectively throughout. Enterprise customers require Type II. ManySignal collects Type II evidence year-round.
Continuous monitoring requirement
CC7.2 (Anomaly Detection) requires ongoing monitoring — not periodic review. ManySignal provides machine-verifiable evidence that the detection system operated continuously, with specific anomaly detection events logged throughout the audit period.
Control mapping — SOC 2 to ManySignal capabilities
| Control ID | Control Name | ManySignal Capability |
|---|---|---|
| CC6.1 | Logical and Physical Access Controls | Privileged access provisioning/deprovisioning monitoring, access review evidence, policy violation detection |
| CC6.2 | Authentication | MFA enforcement monitoring, credential stuffing detection, shared account usage detection |
| CC6.3 | Access Removal | Off-boarding access removal verification — access activity after deprovisioning flagged automatically |
| CC6.6 | Logical Access from Non-Managed Devices | Device compliance state correlated with authentication events — unmanaged device access detected |
| CC6.7 | Information Transmission | Data egress monitoring — unusual volume, unencrypted transmission, and transmission to unexpected destinations |
| CC6.8 | Malicious Code Prevention | Malware indicator detection via endpoint telemetry, process anomaly detection, and file hash reputation |
| CC7.1 | Vulnerability Monitoring | Exploitation attempts against known vulnerabilities detected via IDS signatures and behaviour analytics |
| CC7.2 | Anomalies and Security Events | Full behavioural analytics across identity, network, cloud, and endpoint — machine-verifiable anomaly detection evidence |
| CC7.3 | Event Evaluation | Every alert evaluated by the Triage agent — structured verdict with confidence score before analyst review |
| CC7.4 | Incident Response | Automated response playbooks, case lifecycle management, evidence preservation, and timeline documentation |
| CC7.5 | Incident Response — Identified Incidents | Case management with full incident timeline, affected entity list, and remediation evidence |
| CC9.1 | Risk Mitigation — Vendor Management | Third-party access monitoring — vendor credential anomalies, access scope violations, offboarding verification |
Evidence export for auditors
Auditor portal access
Auditors receive read-only access to the ManySignal evidence portal for the audit period. They can view all detection events, triage verdicts, case timelines, and access review records — without involving your security team.
Period-based evidence export
One-click export of all CC7.2 and CC7.3 evidence for any 12-month period. Timestamped, entity-attributed records in PDF and JSON format. Suitable for direct upload to audit tools (Vanta, Drata, Secureframe, Tugboat Logic).
Integration with GRC platforms
ManySignal integrates with Vanta, Drata, and Secureframe via API. Evidence is automatically pushed to the relevant controls in your GRC platform as it is collected — eliminating manual evidence upload at audit time.
ManySignal SOC 2 Type II report
ManySignal's SOC 2 Type II report (Security, Availability, and Confidentiality criteria) is available under NDA at trust@manysignal.com. The report covers the prior calendar year and is produced by a PCAOB-registered CPA firm. The report is typically provided within 2 business days of NDA execution.
SOC 2 compliance — auditor questions
Can ManySignal reduce the effort required for our annual SOC 2 Type II audit?
Yes. ManySignal collects machine-verifiable evidence continuously for all five Trust Services Criteria. At audit time, the platform generates an evidence package per criteria with timestamped, auditor-readable records for the full audit period. Customers report reducing audit preparation time by 60–80% after the first year on ManySignal — because evidence collection is automated year-round rather than assembled manually at audit time.
Does ManySignal itself have a SOC 2 Type II report?
Yes. ManySignal's SOC 2 Type II report is available under NDA at trust@manysignal.com. The audit period covers the full prior calendar year. The report covers the Security, Availability, and Confidentiality Trust Services Criteria. The auditor is a PCAOB-registered CPA firm.
How does ManySignal provide evidence for CC7.2 (Anomaly Detection) specifically?
CC7.2 requires the entity to detect and monitor for anomalies in system behaviour. ManySignal provides machine-verifiable evidence: for each alert fired during the audit period, the platform records the detection timestamp, the specific indicator that triggered it, the anomaly score, the triage verdict, and the analyst action taken. This creates an auditor-readable history of the anomaly detection system operating continuously throughout the audit period.
Can ManySignal provide evidence for all five SOC 2 Trust Services Criteria (CC, A, C, PI, P)?
ManySignal primarily covers Security (CC) and Confidentiality (C) criteria directly. For Availability (A), ManySignal's infrastructure uptime monitoring and incident management contribute evidence. Processing Integrity (PI) evidence typically comes from application-layer controls outside ManySignal's scope. Privacy (P) evidence is supported through ManySignal's data access monitoring and breach detection capabilities. The specific criteria in scope depend on which Trust Services Criteria your certification covers.
How does ManySignal handle the access review evidence required for CC6.1?
CC6.1 requires the entity to register and authorise internal and external users. ManySignal monitors every access provisioning and deprovisioning event, flags users who retain access after role changes or terminations, and generates an access review evidence package covering the full audit period. This includes: all access grants, access reviews performed, access removed, and any policy violations detected.
Start collecting SOC 2 evidence today
Connect your cloud provider, identity, and endpoint telemetry. ManySignal begins collecting auditor-ready evidence from the first day of your deployment — so your next Type II audit has 12 months of continuous evidence.